Title: Use Your Illusion: Secure Authentication Usable Anywhere
1Use Your IllusionSecure Authentication Usable
Anywhere
- Eiji Hayashi
- Nicolas Christin
- Rachna Dhamija
- Adrian Perrig
- Carnegie Mellon CyLab Japan
2Key Concept Distortion
You can recognize a baby now because you know the
original picture
3Use Your Illusion
4Graphical Authentication
- Passfaces
- Pass Points
- DAS (Draw-A-Secret)
- Déjà vu
5Passfaces
- Faces are used as a graphical portfolio
- Preference could be a limitation
Cited from On User Choice in Graphical Password
Schemes, Darren Daivis et. al, 2004
6Pass Points
- Use a sequence of clicks as a shared secret
- There are hot spots
Cited from Authentication Usin Graphical
Passwords Basic Results, Susan Wiednbeck et.
al, 2004
7Most Straightforward Way
- Choose graphical portfolio from a set of pictures
8Graphical Portfolio
- If a user can choose whatevergraphical
portfolio - If system assigns portfoliorandomly
9Fundamental Tradeoff
Security
Memorability
10Use Your Illusion
- Allow users to take/choose pictures by themselves
- Distort the pictures
- Assign the distorted pictures as graphical
portfolio
11Use Your Illusion
- Allow users to take/choose pictures by themselves
- Distort the pictures
- Assign the Distorted pictures as graphical token
Security
Memorability
12Requirements for Distortion
- One-way
- Discarding precise shapes and colors
- Preserving rough shapes and colors
13Oil Painting Filter
- Choose RGB values which appears most frequently
in a neighborhood
14Oil Painting Filter
15Distortion Level
- If high, difficult to guessbut difficult to
memorize - If low, easy to memorizebut easy to guess
16Distortion Level
- Two parameters affect distortion level
- If too high, not usable
- If too low, not secure
Security
Memorability
17Low-Fidelity Test
Least distorted
Most distorted
18Low-Fidelity Test
19Low-Fidelity Test
20Low-Fidelity Test
21Low-Fidelity Test
22Low-Fidelity Test
23Low-Fidelity Test
Its a dog!!
24Low-Fidelity Test
Difficult to guess w/o knowing original picture
25Low-Fidelity Test
Cant recognize a dog
26Low-Fidelity Test
Easy to recognize w/ knowing original picture
27Low-Fidelity Test
Satisfies requirements
28Prototype
- Implemented on Nokias cell-phone for usability
test - Also implemented on the web
29Prototype
Demo
30Usability Test
- 45 participants and for 1 week
- 54 participants and for 4 weeks
311st Usability Test
- 45 participants were divided into 3 groups
- Self-selected, Non-distorted
- Self-selected, distorted (Use Your Illusion)
- Imposed, highly-distorted
32Self-selected, Non-distorted
33Self-selected, Distorted
34Imposed, Highly-distorted
35Procedure
36Success Rate
37Authentication Time (Mean)
Imposed, Highly-distorted
Self-selected, Distorted
Self-selected, Non-distorted
38Process of Memorization
- Participants assign meanings to distorted
pictures - Assigning meanings helps memorization
Mountain
Sea
Moai statue
392nd Usability Test
- 54 participants were divided into 3 groups
- Self-selected, Non-distorted
- Self-selected, Distorted
- Imposed, Distorted
- Authenticate
- On the 1st day
- 2 days after
- 1 week after
- 4 weeks after
40Imposed, Distorted
41Success Rate
42Authentication Time (Mean)
Imposed, Distorted
Self-selected, Distorted
Self-selected, Non-distorted
43Tolerance against Guessing Attack
- Original pictures are vulnerable
- Distorted pictures are more tolerant
44Future Work
- Detailed usability test
- Long term test
- Find an optimal distortion
- Investigate a metric evaluating distortion level
45Use Your Illusion
- Use distorted pictures as a portfolio
- As memorable as non-distorted pictures
- More memorable than imposed (highly-) distorted
pictures - Fits human memorization process
- More tolerant to guessing attack
46Thank you for listening Prototype is available
on http//arima.okoze.net/illusion/ Please try it!